CVE-2010-1338
teamsite_hack_plugin < 3.0 - SQL Injection via ts_other.php userid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1338. PoCs published by Easy Laster.
AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in Woltlab Burning Board Teamsite Hack V3.0 via the 'ts_other.php' file. It extracts user credentials (ID, username, password, and email) by injecting a UNION-based SQL query.
Description
SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.
Exploits (1)
This Python script exploits a SQL injection vulnerability in Woltlab Burning Board Teamsite Hack V3.0 via the 'ts_other.php' file. It extracts user credentials (ID, username, password, and email) by injecting a UNION-based SQL query.